# Beats

**URL:** https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=35

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 36

---

## [Help constructing yaml file](https://discuss.elastic.co/t/help-constructing-yaml-file/345550)

<div class="topic-metadata">

**Author:** [@Emorta](https://discuss.elastic.co/u/Emorta)\
**Replies:** 1\
**Last updated:** [October 23, 2023, 9:25am UTC](https://discuss.elastic.co/t/help-constructing-yaml-file/345550 "2023-10-23T09:25:05Z")

</div>

Hello, I'm trying to monitor Windows events (security only) and DHCP event logs (files). The first part works well; logs are collected and shipped, and it has been running for 3 months. I now want to add file logging for…

---

## [Filebeat Grok pattern for access log](https://discuss.elastic.co/t/filebeat-grok-pattern-for-access-log/345455)

<div class="topic-metadata">

**Author:** [@tucker](https://discuss.elastic.co/u/tucker)\
**Replies:** 5\
**Last updated:** [October 20, 2023, 6:52pm UTC](https://discuss.elastic.co/t/filebeat-grok-pattern-for-access-log/345455 "2023-10-20T18:52:15Z")

</div>

Hi, I have an access log for which I am trying to write a Grok pattern but in the filebeat log, I always see "Provided Grok expressions do not match field value:". The log entries look like: \[20/Oct/2023:09:52:33 +000…

---

## [How can i increment cursor by one for each run in httpjson](https://discuss.elastic.co/t/how-can-i-increment-cursor-by-one-for-each-run-in-httpjson/345421)

<div class="topic-metadata">

**Author:** [@German\_Bravo](https://discuss.elastic.co/u/German_Bravo)\
**Replies:** 0\
**Last updated:** [October 19, 2023, 10:16pm UTC](https://discuss.elastic.co/t/how-can-i-increment-cursor-by-one-for-each-run-in-httpjson/345421 "2023-10-19T22:16:54Z")

</div>

Hi im using the httpjson input module in filebeat and im trying to achieve the following without any luck In words: I need to fetch an API every 10s In the first run i need to set query param page = 0 In the following…

---

## [Sysmon/Sysmon64 not visible in metricbeats for sysmon version 15](https://discuss.elastic.co/t/sysmon-sysmon64-not-visible-in-metricbeats-for-sysmon-version-15/345308)

<div class="topic-metadata">

**Author:** [@shani\_angarkadu](https://discuss.elastic.co/u/shani_angarkadu)\
**Replies:** 5\
**Last updated:** [October 19, 2023, 8:29pm UTC](https://discuss.elastic.co/t/sysmon-sysmon64-not-visible-in-metricbeats-for-sysmon-version-15/345308 "2023-10-19T20:29:36Z")

</div>

Hi there, We are using the system module and metricsets process. I can see all the other CPU/memory metrics except the Sysmon. Sysmon is completely missing in the output. Here is my system.yml - module: system per…

---

## [Huge packets sent from filebeat to ES](https://discuss.elastic.co/t/huge-packets-sent-from-filebeat-to-es/345343)

<div class="topic-metadata">

**Author:** [@hjazz6](https://discuss.elastic.co/u/hjazz6)\
**Replies:** 1\
**Last updated:** [October 19, 2023, 11:49am UTC](https://discuss.elastic.co/t/huge-packets-sent-from-filebeat-to-es/345343 "2023-10-19T11:49:02Z")

</div>

Hi all, I'm using the netflow module on filebeat v8.8.0 to send netflow traffic to ES. The incoming netflow packets are all about 5KB to 6KB. When I did a tcpdump on the interface that is sending the netflow data to ES,…

---

## [System/socket dataset setup failed: guess\_struct\_creds](https://discuss.elastic.co/t/system-socket-dataset-setup-failed-guess-struct-creds/344175)

<div class="topic-metadata">

**Author:** [@0xdeadbeer](https://discuss.elastic.co/u/0xdeadbeer)\
**Replies:** 2\
**Last updated:** [October 19, 2023, 11:46am UTC](https://discuss.elastic.co/t/system-socket-dataset-setup-failed-guess-struct-creds/344175 "2023-10-19T11:46:06Z")

</div>

Auditbeat runs flawlessly without the socket module. However, whenever I turn it on the following error shows up: {"log.level":"info","@timestamp":"2023-09-30T20:01:20.511+0200","log.origin":{"file.name":"instance/beat.…

---

## [Sql module, pb with DB password characters](https://discuss.elastic.co/t/sql-module-pb-with-db-password-characters/345375)

<div class="topic-metadata">

**Author:** [@ppic](https://discuss.elastic.co/u/ppic)\
**Replies:** 0\
**Last updated:** [October 19, 2023, 10:02am UTC](https://discuss.elastic.co/t/sql-module-pb-with-db-password-characters/345375 "2023-10-19T10:02:27Z")

</div>

Hello, I use Elastic 7.17 with metricbeat and the sql module. The DB connection fails with this line in the log: error opening connection: testing connection: parse "sqlserver://elk:J6": invalid port ":J6" after host …

---

## [Filebeat cat not erich with metadata after 5 min when using add\_kubernetes\_metadata](https://discuss.elastic.co/t/filebeat-cat-not-erich-with-metadata-after-5-min-when-using-add-kubernetes-metadata/345369)

<div class="topic-metadata">

**Author:** [@aisuhua](https://discuss.elastic.co/u/aisuhua)\
**Replies:** 0\
**Last updated:** [October 19, 2023, 8:54am UTC](https://discuss.elastic.co/t/filebeat-cat-not-erich-with-metadata-after-5-min-when-using-add-kubernetes-metadata/345369 "2023-10-19T08:54:59Z")

</div>

When no log was written within 5 minutes，filebeat cat not erich with kubenetes metadata. After I had change logger.level to debug，the debug file like below: kubernetes: Querying for pod failed with error: pods \\"worke…

---

## [How to create data view of metricbeat stack monitoring index in discover(xpack settings used)](https://discuss.elastic.co/t/how-to-create-data-view-of-metricbeat-stack-monitoring-index-in-discover-xpack-settings-used/345234)

<div class="topic-metadata">

**Author:** [@Jason\_Paralta](https://discuss.elastic.co/u/Jason_Paralta)\
**Replies:** 2\
**Last updated:** [October 18, 2023, 6:41pm UTC](https://discuss.elastic.co/t/how-to-create-data-view-of-metricbeat-stack-monitoring-index-in-discover-xpack-settings-used/345234 "2023-10-18T18:41:14Z")

</div>

Hello All, I am trying to monitor my Elastic stack consisting of metricbeat,filebeat,heartbeat and logstash stats to be monitored in discover. Somehow I implemented metricbeat monitoring reading docs using modules.d fol…

---

## [Metricbeat are not collecting all Logstash data](https://discuss.elastic.co/t/metricbeat-are-not-collecting-all-logstash-data/342889)

<div class="topic-metadata">

**Author:** [@Claudio\_Ract\_Costa](https://discuss.elastic.co/u/Claudio_Ract_Costa)\
**Replies:** 5\
**Last updated:** [October 18, 2023, 6:35pm UTC](https://discuss.elastic.co/t/metricbeat-are-not-collecting-all-logstash-data/342889 "2023-10-18T18:35:36Z")

</div>

Hi Community, I have a ELK Stack 8.2. I am trying to configure my Metricbeat to monitoring logstash node to monitore it but, for any reason, Kibana does not show all information of Logstash (like Events Emiited Rate, E…

---

## [Are ingest pipelines created by agent expected to be different from the same type of pipeline created by beats?](https://discuss.elastic.co/t/are-ingest-pipelines-created-by-agent-expected-to-be-different-from-the-same-type-of-pipeline-created-by-beats/345313)

<div class="topic-metadata">

**Author:** [@jerrac](https://discuss.elastic.co/u/jerrac)\
**Replies:** 2\
**Last updated:** [October 18, 2023, 4:43pm UTC](https://discuss.elastic.co/t/are-ingest-pipelines-created-by-agent-expected-to-be-different-from-the-same-type-of-pipeline-created-by-beats/345313 "2023-10-18T16:43:49Z")

</div>

So, I've been assuming that the ingest pipelines created by Elastic Agent and those created by Filebeat, would be pretty much identical. I expected some differences, but nothing that would make them output different fiel…

---

## [How to start Metricbeat as non root user?](https://discuss.elastic.co/t/how-to-start-metricbeat-as-non-root-user/344712)

<div class="topic-metadata">

**Author:** [@Gorkem\_Keskin](https://discuss.elastic.co/u/Gorkem_Keskin)\
**Replies:** 1\
**Last updated:** [October 18, 2023, 10:05am UTC](https://discuss.elastic.co/t/how-to-start-metricbeat-as-non-root-user/344712 "2023-10-18T10:05:00Z")

</div>

Hello, I am sending logs using Metricbeat system module to Elasticsearch. I have to send as a non root user, however it keeps on sending both as non root and root user. I tried to follow documentations to send only as n…

---

## [Fielddata is disabled on \[host.hostname\] in \[filebeat-8.10.4-2023.10.17\]](https://discuss.elastic.co/t/fielddata-is-disabled-on-host-hostname-in-filebeat-8-10-4-2023-10-17/345246)

<div class="topic-metadata">

**Author:** [@whanklee](https://discuss.elastic.co/u/whanklee)\
**Replies:** 5\
**Last updated:** [October 18, 2023, 8:07am UTC](https://discuss.elastic.co/t/fielddata-is-disabled-on-host-hostname-in-filebeat-8-10-4-2023-10-17/345246 "2023-10-18T08:07:28Z")

</div>

Hi there, I got the following error code: Index: filebeat-8.10.4-2023.10.17 Type: illegal\_argument\_exception Node: rQ6bZR\_YQ3Ken74LUR-Oaw Reason: Fielddata is disabled on \[host.hostname\] in \[filebeat-8.10.4-2023.10.…

---

## [Winlogbeat causing high CPU utilization](https://discuss.elastic.co/t/winlogbeat-causing-high-cpu-utilization/344972)

<div class="topic-metadata">

**Author:** [@momher](https://discuss.elastic.co/u/momher)\
**Replies:** 3\
**Last updated:** [October 18, 2023, 6:18am UTC](https://discuss.elastic.co/t/winlogbeat-causing-high-cpu-utilization/344972 "2023-10-18T06:18:59Z")

</div>

Winlogbeat is causing high CPU utilization in one of our Domain Controller Server. It happens the same time of the day and it's been re-occurring and alerted 3x for this month. Winlogbeat version - 7.17.9

---

## [Filebeat not sending logs to EKS in a Microk8s Kubernetes environment](https://discuss.elastic.co/t/filebeat-not-sending-logs-to-eks-in-a-microk8s-kubernetes-environment/345221)

<div class="topic-metadata">

**Author:** [@NashF](https://discuss.elastic.co/u/NashF)\
**Replies:** 0\
**Last updated:** [October 17, 2023, 2:20pm UTC](https://discuss.elastic.co/t/filebeat-not-sending-logs-to-eks-in-a-microk8s-kubernetes-environment/345221 "2023-10-17T14:20:43Z")

</div>

I'm at my wits end with this ELK stack and Filebeat. Currently using Elasticsearch, Kibana ,Filebeat all version 8.10.2 and logstash logstash-logback-encoder:7.4 for converting my springboot microservice logs into json o…

---

## [Stopping/uninstalling Winlogbeat 8.8.2 fails](https://discuss.elastic.co/t/stopping-uninstalling-winlogbeat-8-8-2-fails/345209)

<div class="topic-metadata">

**Author:** [@ben-sec](https://discuss.elastic.co/u/ben-sec)\
**Replies:** 1\
**Last updated:** [October 17, 2023, 1:00pm UTC](https://discuss.elastic.co/t/stopping-uninstalling-winlogbeat-8-8-2-fails/345209 "2023-10-17T13:00:29Z")

</div>

Hello! I have problems with Winlogbeat 8.8.2 on 5% of my clients (service is running but I don't get any logs) and want to get rid of it, but I'm unable to stop the service and to uninstall Winlogbeat. Is there any kind…

---

## [After AKS Node Restart - We have lost Disk Queue](https://discuss.elastic.co/t/after-aks-node-restart-we-have-lost-disk-queue/345158)

<div class="topic-metadata">

**Author:** [@zoheb](https://discuss.elastic.co/u/zoheb)\
**Replies:** 0\
**Last updated:** [October 17, 2023, 5:22am UTC](https://discuss.elastic.co/t/after-aks-node-restart-we-have-lost-disk-queue/345158 "2023-10-17T05:22:51Z")

</div>

Hi Team, Yesterday we have restarted our AKS Nodes and we have lost the disk queue. We see a new folder being created at AKS Node. Here is the configuration file for filebeat: volumeMounts: - name: config mountPath:…

---

## [Filebeat not collecting logs from EKS](https://discuss.elastic.co/t/filebeat-not-collecting-logs-from-eks/344939)

<div class="topic-metadata">

**Author:** [@rp346](https://discuss.elastic.co/u/rp346)\
**Replies:** 1\
**Last updated:** [October 16, 2023, 6:26pm UTC](https://discuss.elastic.co/t/filebeat-not-collecting-logs-from-eks/344939 "2023-10-16T18:26:25Z")

</div>

I have deployed EBK (8.5.3) stack on AWS EKS with following manifest filebeat.yaml--- apiVersion: rbac.authorization.k8s.io/v1 kind: ClusterRoleBinding metadata: name: filebeat subjects: - kind: ServiceAccount name…

---

## [Filebeat/Logstash poor disk.queue read performance: is that the maximum i can get?](https://discuss.elastic.co/t/filebeat-logstash-poor-disk-queue-read-performance-is-that-the-maximum-i-can-get/345056)

<div class="topic-metadata">

**Author:** [@sergeyarl](https://discuss.elastic.co/u/sergeyarl)\
**Replies:** 2\
**Last updated:** [October 16, 2023, 5:53pm UTC](https://discuss.elastic.co/t/filebeat-logstash-poor-disk-queue-read-performance-is-that-the-maximum-i-can-get/345056 "2023-10-16T17:53:28Z")

</div>

Testing performance of Filebeat disk.queue. Environment: AWS EC2 OS: Centos 7.x Machine parameters (FB, LS): CPU 8 vcores, RAM 16GB Filebeat version: filebeat-8.10.3-1.x86\_64 Logstash version: logstash-8.10.3-1.x86\_…

---

## [Use winlogbeat to convert windows event logs to json?](https://discuss.elastic.co/t/use-winlogbeat-to-convert-windows-event-logs-to-json/345126)

<div class="topic-metadata">

**Author:** [@mathurin68](https://discuss.elastic.co/u/mathurin68)\
**Replies:** 0\
**Last updated:** [October 16, 2023, 4:00pm UTC](https://discuss.elastic.co/t/use-winlogbeat-to-convert-windows-event-logs-to-json/345126 "2023-10-16T16:00:30Z")

</div>

Is it still possible to use winlogbeat to convert evtx files to json? I was trying to use the powershell script from here - If(Test-Path -path $pwd\\winlogbeat.exe) { echo "Starting conversion from EVTX to JSON ..."…

---

## [Timestamp format](https://discuss.elastic.co/t/timestamp-format/344951)

<div class="topic-metadata">

**Author:** [@hta](https://discuss.elastic.co/u/hta)\
**Replies:** 9\
**Last updated:** [October 16, 2023, 1:02pm UTC](https://discuss.elastic.co/t/timestamp-format/344951 "2023-10-16T13:02:47Z")

</div>

We get the timestamps in this format: '2023-10-01T01:22:33.123Z'. Where can I set the format? And which time zone is preset? How can I find out the timezone from the timestamp? Is that UTC? We use filebeat agents to co…

---

## [Failed to start crawler: starting input failed: error while initializing input: No paths were defined for input accessing](https://discuss.elastic.co/t/failed-to-start-crawler-starting-input-failed-error-while-initializing-input-no-paths-were-defined-for-input-accessing/345085)

<div class="topic-metadata">

**Author:** [@Manula\_Manjitha](https://discuss.elastic.co/u/Manula_Manjitha)\
**Replies:** 0\
**Last updated:** [October 16, 2023, 9:29am UTC](https://discuss.elastic.co/t/failed-to-start-crawler-starting-input-failed-error-while-initializing-input-no-paths-were-defined-for-input-accessing/345085 "2023-10-16T09:29:27Z")

</div>

I have configured two filebeat inputs which the type of them is log. filebeat.inputs: - type: log id: gateway-elk enabled: true paths: - /home/ggg/app/ntp\_gateway/gateway-elk.log fields: {log\_type: gatewayl…

---

## [Filebeat stops sending logs to logstash, "message":"Harvester could not be started on existing file](https://discuss.elastic.co/t/filebeat-stops-sending-logs-to-logstash-message-harvester-could-not-be-started-on-existing-file/345048)

<div class="topic-metadata">

**Author:** [@aleem](https://discuss.elastic.co/u/aleem)\
**Replies:** 0\
**Last updated:** [October 15, 2023, 12:46pm UTC](https://discuss.elastic.co/t/filebeat-stops-sending-logs-to-logstash-message-harvester-could-not-be-started-on-existing-file/345048 "2023-10-15T12:46:22Z")

</div>

Filebeat stops sending logs to logstash and needs a manual restart to resume. Logs for specific containers are stopped, while other container's logs are still going to logstash. {"log.level":"error","@timestamp":"2023-1…

---

## [Developer reference and config value validation](https://discuss.elastic.co/t/developer-reference-and-config-value-validation/345016)

<div class="topic-metadata">

**Author:** [@tlinker13](https://discuss.elastic.co/u/tlinker13)\
**Replies:** 0\
**Last updated:** [October 13, 2023, 8:46pm UTC](https://discuss.elastic.co/t/developer-reference-and-config-value-validation/345016 "2023-10-13T20:46:20Z")

</div>

Hey all, Background: I have to implement a new module and metricset to search LDAP directories. MY config.yml shall look somewhat like that: - module: ldap metricsets: \["ldapsearch"\] enabled: true period: 10s …

---

## [AWS Lambda end of support for the Go 1.x runtime](https://discuss.elastic.co/t/aws-lambda-end-of-support-for-the-go-1-x-runtime/344983)

<div class="topic-metadata">

**Author:** [@ssdrosos](https://discuss.elastic.co/u/ssdrosos)\
**Replies:** 2\
**Last updated:** [October 13, 2023, 1:28pm UTC](https://discuss.elastic.co/t/aws-lambda-end-of-support-for-the-go-1-x-runtime/344983 "2023-10-13T13:28:53Z")

</div>

Hello, AWS has announced that they will stop the support of the Go 1.x runtime environment. From what I can see in the latest master Dockerfile, the go runtime is still v1: https://github.com/elastic/beats/blob/main/x-…

---

## [Exiting: index management requested but the Elasticsearch output is not configured/enabled](https://discuss.elastic.co/t/exiting-index-management-requested-but-the-elasticsearch-output-is-not-configured-enabled/344980)

<div class="topic-metadata">

**Author:** [@pramod\_1](https://discuss.elastic.co/u/pramod_1)\
**Replies:** 0\
**Last updated:** [October 13, 2023, 10:06am UTC](https://discuss.elastic.co/t/exiting-index-management-requested-but-the-elasticsearch-output-is-not-configured-enabled/344980 "2023-10-13T10:06:49Z")

</div>

I have executed the below command filebeat setup -e got this error from the above command. {"log.level":"warn","@timestamp":"2023-10-13T15:33:15.664+0530","log.origin":{"file.name":"beater/filebeat.go","file.line":193…

---

## [Auditbeat process memory grows every day](https://discuss.elastic.co/t/auditbeat-process-memory-grows-every-day/344061)

<div class="topic-metadata">

**Author:** [@v1k1ng0](https://discuss.elastic.co/u/v1k1ng0)\
**Replies:** 6\
**Last updated:** [October 13, 2023, 8:32am UTC](https://discuss.elastic.co/t/auditbeat-process-memory-grows-every-day/344061 "2023-10-13T08:32:53Z")

</div>

Hi, not sure if happening in all of my servers (vmware virtual servers), but I have 2 servers with antivirus installed (trend micro deep security) and auditbeat installed happening that auditbeat process memory grows 2%…

---

## [Winlogbeats error when using xml\_query](https://discuss.elastic.co/t/winlogbeats-error-when-using-xml-query/344936)

<div class="topic-metadata">

**Author:** [@rojjin](https://discuss.elastic.co/u/rojjin)\
**Replies:** 6\
**Last updated:** [October 13, 2023, 7:46am UTC](https://discuss.elastic.co/t/winlogbeats-error-when-using-xml-query/344936 "2023-10-13T07:46:31Z")

</div>

Winlogbeats logs an error when trying to use an xml\_query to return custom events. I have read thru the documentation and believe the config is correct. Here is the config: output.logstash: hosts: \["server"\] path: d…

---

## [Error: Forbidden curl https://artifacts.elastic.co/GPG-KEY-elasticsearch](https://discuss.elastic.co/t/error-forbidden-curl-https-artifacts-elastic-co-gpg-key-elasticsearch/344832)

<div class="topic-metadata">

**Author:** [@qwerty1q2w](https://discuss.elastic.co/u/qwerty1q2w)\
**Replies:** 3\
**Last updated:** [October 12, 2023, 2:13pm UTC](https://discuss.elastic.co/t/error-forbidden-curl-https-artifacts-elastic-co-gpg-key-elasticsearch/344832 "2023-10-12T14:13:11Z")

</div>

Hello! I can't download GPG key from hetzner server. request - curl https://artifacts.elastic.co/GPG-KEY-elasticsearch response 403 Forbidden our client does not have permission to get URL from this server.

---

## [Filebeat service failing after certain time](https://discuss.elastic.co/t/filebeat-service-failing-after-certain-time/344896)

<div class="topic-metadata">

**Author:** [@parvvam](https://discuss.elastic.co/u/parvvam)\
**Replies:** 0\
**Last updated:** [October 12, 2023, 10:45am UTC](https://discuss.elastic.co/t/filebeat-service-failing-after-certain-time/344896 "2023-10-12T10:45:39Z")

</div>

I am using filebeat 7.11.1 to push logs to logstash on a different server where logstatsh and Elasticsearch are installed. The service of filebeat fails after a certain time. It works properly for a minute or two withou…

[Previous page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=34)

[Next page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=36)
